Back to skill

Security audit

marketing-ideas

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk marketing-ideation skill that reads a narrowly named product-marketing context file if present and otherwise provides strategy suggestions.

Install only if you want Codex to use a marketing-ideas playbook for SaaS/software growth questions. Be aware it may activate on broad growth-ideation phrasing and may read local product-marketing context files if those exist.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description contains very broad trigger phrases such as 'what else can I try,' 'brainstorm marketing,' and 'I don't know how to market this,' which can match many generic ideation requests. In an agent-routing system, this can cause the marketing skill to activate outside narrowly intended product-marketing contexts, leading to inappropriate context loading and overreach into unrelated conversations.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The eval explicitly expects the skill to trigger on vague, casual phrasing, but it does not define clear boundaries for when the marketing-ideas skill should activate versus when a more specific skill should handle the request. In an agent-routing system, this can cause overbroad invocation, misclassification of user intent, and accidental interception of requests better handled by other skills, reducing reliability and potentially bypassing safer or more specialized workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.